1 reviews | Active since Nov 2013
Two years ago (28/02/2014) I discovered that HelloPeter.com was storing passwords in plain-text (a very big security no no that means it makes no effort to protect all its users passwords). I reported this issue to the company and was sent an e-mail that said:<br> <br> \I have been advised that this portion of the website is a legacy system that is positioned to be upgraded to a more secure platform.\"<br> <br> Just now, 2 years later, I discovered that they haven't actually done anything about it. This is misleading to its customers, suggests a low regard for security and also a very dangerous practice which can be fixed in four lines of copy/paste coder.<br> <br> For the benefit of those that don't know, what HelloPeter is doing means:<br> - any of its employees can read your password if they access the database and then try your e-mail and password combination on GMail, Twitter, etc<br> - if a hacker gets into their system, the person can try your e-mail and password combination on Facebook, FNB, etc (this has actually happened to companies like Sony and LinkedIn)<br> <br> I want to stress that all of these dangers are practically non-existent if they make a few simple changes to their password management."
Best regards,
Best regards,
© Copyright 2026 hellopeter.com and its affiliates. All rights reserved.